DeSlopTry DeSlop →

Plain-language privacy

What we send and store.

Your writing stays in your browser until you submit it for a rewrite. Anonymous and Free rewrites require agreement to contribute submitted drafts and their results. We retain those contributions for 30 days to evaluate and improve our edits and prepare training examples for our writing models. We do not use writing submitted on Pro for engine improvement or training. Writing is never included in product analytics.

01

Writing contributions

Before a free rewrite, we ask you to explicitly agree to contribute the draft you submit and its result. Agreement is required for anonymous and Free use. If you don’t agree, you can choose Pro or leave without submitting. Reading these terms or signing up does not by itself give agreement. We ask once, before your first free rewrite, and remember your answer in this browser for your account (or guest session) until you stop contributing or the notice changes.

We store contributions separately from analytics and billing in an encrypted AWS database in Canada. Each record includes the agreement version, acceptance time, an account or guest-session identifier derived with a secret key, the engine version, model route, selected tone, and the rewrite outcome. We do not attach your email, IP address, payment details, or My Voice samples.

Authorized reviewers may read contributions to check editing quality and prepare training examples. Contributions are not automatically approved for training, published, sold, or sent to a training provider. Review does not extend their 30-day expiry. Any later training workflow must preserve that expiry and respect deletion requests.

Contributions expire 30 days after submission. Our hourly cleanup job deletes expired records; AWS expiry deletion is an additional safeguard and may run later. We do not enable backups for this writing store. Content-free deletion state is kept to prevent an in-flight request from restoring writing you deleted.

Use Delete contributed writing beside the editor to delete contributions associated with your signed-in account or current guest session. This clears your agreement in that page; another free submission requires agreement again. Keep your guest cookie to retain access to guest deletion. If you lose it, the contributions still expire after 30 days. Account deletion and guest deletion are separate because we do not automatically link their writing.

Writing submitted on Pro is processed temporarily for your rewrite and excluded from this collection. Upgrading does not delete earlier Free contributions; use the deletion button to remove those too. Saved drafts that you have not submitted and raw My Voice samples are not collected.

02

Your browser workspace

Browser checks do not consume a rewrite or send your text to our servers. When you are signed in, the workspace can save up to 50 drafts for your account in this browser. A saved draft can contain up to 20,000 characters in its original and result fields. You can export drafts as text files. Saving a draft does not upload it or sync it to another browser. Submitting it for a free rewrite is covered by the contribution terms above.

Writing preferences, local usage counts, your voice contract, and derived My Voice features are also stored for the signed-in account in this browser. On deslopit.com, your voice contract and preferences are stored in this browser without an account. Raw samples used to build a My Voice profile are not saved. The workspace at app.deslopit.com does not run product analytics.

03

When you request a rewrite

Nothing is sent for rewriting until you click DeSlop it. That explicit action sends the current draft to our servers for one rewrite. We check your allowance and reserve a rewrite before processing your request. If processing fails, we release the reservation. Rejected AI rewrites and unchanged results also release the reservation. Completed rewrites count toward the applicable guest, Free, or Pro limit. Separate request limits apply to attempts, including attempts that do not use your rewrite allowance.

For eligible requests, we may send sections of your draft, derived voice-style guidance when enabled (style numbers plus at most three common opening words and two common filler words from your samples), and generated responses through OpenRouter to the routed model provider. When a voice contract is active, the whole contract is sent to our servers, which apply it; only its tone and rhythm settings and any banned phrases that already appear in your draft are forwarded to the model provider. Contracts are not stored with contributions. We ask for up to three candidate rewrites in one request, discard any that fail our meaning and preservation checks, and rank the rest with our own scoring. For anonymous and Free use, we retain the submitted draft and result as explained above. We do not retain Pro writing for improvement or training. OpenRouter and the routed provider process that content under their own retention and security terms; we request providers that deny data collection. Review a returned rewrite against the original before copying it.

Cloudflare Turnstile protects the shared rewrite service from automated abuse. Cloudflare receives the browser and connection signals needed to verify the request; the draft itself is not sent to Cloudflare Turnstile.

04

Optional grammar review

When we offer a grammar review, nothing is sent until you click Fix this sentence. Only the quoted sentence is sent to our servers for temporary processing. We do not store that sentence. The surrounding draft is not sent, and the suggestion is never applied automatically. For the review, the sentence passes through OpenRouter to the routed model provider. Those services may handle it under their own retention and security terms; we request providers that deny data collection.

05

Analytics and abuse protection

On the marketing site, we record product events such as page views, cleanup completion, copy actions, preference names, engine version, local session draft order, numeric text and per-category change counts, time to copy, whether copy-and-next led to another completed draft, whether you edited a result before copying, whether the final version became shorter or longer, whether the optional question asking for a specific detail was offered, applied, or dismissed, its question category and answer length, whether generated changes were opened for review, whether an AI rewrite succeeded and how many candidates were drafted and passed, whether a voice contract was active and which preset or action changed it, the numeric voice scores before and after, and whether the preservation receipt passed. The reviewed words, question answer, draft, result, edited text, contract terms, and extracted writing features are never included. Grammar-review analytics record only the interaction state, sentence length and processing time. It does not include the sentence or suggestion. The signed-in workspace at app.deslopit.com does not run this product analytics.

A guest trial allows three completed rewrites in one browser. We store a random trial token in an essential __Host-deslop_trial cookie for one year. The cookie is Secure, HttpOnly, SameSite=Lax, and limited to the host-wide path. We store a SHA-256 digest of the token instead of the token itself. A shared-network abuse cap allows three guest rewrites per UTC day. We apply a keyed HMAC to the network identity (the IPv4 address or IPv6 /64 prefix), with a separate scope for trial issuance and rewrites. A network can create up to five new trial sessions per UTC day. Raw IP addresses are not stored in the rate-limit database. A separate hourly attempt counter uses a SHA-256 digest of the network identity and expires five minutes after the hour ends. It includes failed and unchanged attempts. Daily counter records expire seven days after the applicable UTC-day reset. Completed rewrite-request records are scheduled for deletion after two days. Records needed to recover an interrupted rewrite may remain until seven days after that day’s UTC reset for accounts, or for up to one year for guests. These records contain request identifiers and usage counts, never your writing. AWS may delete expired records later.

06

Accounts, Pro billing, and access

Signing in uses Clerk for authentication. Clerk handles email-based sign-in and sends verification codes to confirm it's you. We never see or store a password. To prove you are signed in, your browser sends us a short-lived session token (a JWT) with each authorized request; we verify its claims in memory and do not log or store the token, your email, or the other claims inside it.

To run Pro billing, we keep your opaque Clerk user identifier, Stripe customer and subscription identifiers, subscription status and billing-period end, checkout attempt and session records, and the event identifiers and timestamps needed to process Stripe updates safely. Per-day counters enforce 10 Free rewrites or 100 Pro rewrites per UTC day. Checkout records can temporarily include the Stripe-hosted checkout URL. Stripe handles payment details and subscription management. Your browser keeps a random checkout-attempt identifier while a checkout is pending. We clear it after the subscription reaches a confirmed or terminal state. Your drafts, rewrite results, and voice profile are never sent to Clerk or Stripe.

07

The DeSlop API

You can create API keys in your workspace and call DeSlop from your own server. We store each key only as a SHA-256 hash, so we can't show it to you again. Alongside the hash we keep the key's name, its last four characters, your account's user identifier, and when you created it. Revoking a key stops it working.

Text sent through the API is processed in memory and never logged. Acheck runs on our engine only and never stores your text. A rewrite goes through the same model route described in “When you request a rewrite” above. On a Free-plan key, a rewrite requires the contribution agreement, and we keep that text and its result for 30 days after submission. We never keep text sent with a Pro key. Rate limits and quotas are counted per key and per account; those counters never contain your writing.

08

Use judgment with sensitive writing

Do not send confidential, regulated, legal, medical, or similarly sensitive text for an AI rewrite. Browser-only checks do not send the draft to our servers.

Read our terms of use.

Effective September 24, 2026.